Privacy policy
Effective date: 25 July 2026
What we collect
When you open a Studio account we collect your email address and the sign-in identifiers our authentication provider issues, plus whatever you put on your artist or studio profile: name, handle, bio, location, styles, portfolio and flash images, opening hours, and links. Running your studio produces a second kind of data, and most of it is about your clients rather than about you. That includes the client records you create or import, the messages and images exchanged in an AI consultation on your public page, booking requests and the contact details attached to them, projects, tasks, session dates, sketches, proposals, and whether a deposit or balance has been marked as received. We also keep a light operational layer: page views and feature events, error reports, IP-derived region, browser and device type, and timestamps. Subscription billing runs through Stripe, which shares plan, status, billing country, and receipt details with us. We never see or store full card numbers.
How we use it
We use this data to do the job the product exists for: run the AI intake on your public page, turn conversations into structured briefs, keep projects and schedules straight, send booking confirmations and reminders, generate concept sketches, produce proposals and collection reports, and keep your subscription and quota accurate. A few named providers process data on our behalf: Clerk for sign-in, Supabase for the database, Cloudflare for hosting and image storage, Stripe for subscription billing, Resend for transactional email, and Google and OpenAI for the AI consultation and concept sketches. They are bound to use it only to deliver these features. We do not sell personal data, and we do not use your clients' consultation content to train our own models. Aggregate, non-identifying usage figures may inform which features we build next. One distinction matters here. For your own account we decide how the data is handled. For the client data that flows through your studio, you decide — we process it on your instructions, and it stays yours.
A note on health information
Tattooing touches on health. In an AI consultation a client may mention allergies, skin conditions, medication, pregnancy, or how a previous session healed, either because the assistant asked or because they volunteered it. In many countries this counts as a special category of personal data with stricter rules. That is why the consultation form carries an explicit consent checkbox: a client has to tick it before the conversation is sent, and they are told the studio will use what they share to review the request and follow up. We use these details only to build the brief and pass it to you. We do not use them for advertising, profiling, or any decision that gets made without a person involved. A client can withdraw consent at any time by asking the studio, and the studio can delete the consultation from the dashboard. This is not medical advice and it is not a substitute for the health screening you carry out before working on someone.
How long we keep it
Account and profile data stays for as long as your Studio account is open. Client records, consultations, projects, bookings, and proposals stay until you delete them or close your account, because you need that history to run the business and answer questions about past work. When an account is closed we delete or anonymize the data tied to it. Two things outlive that: payment and subscription records we have to keep for tax, accounting, and chargeback purposes, and security or abuse logs we keep for a limited period. Uploaded and generated images are removed together with the project they belong to. Backups roll over on their own schedule, so a deleted item can persist in backup for a short window before it is overwritten.
Your rights
You can ask us to show you the personal data we hold about your account, correct it, export it, or delete it. Write to studio@openink.ai from your account email so we can verify who you are. We answer within 30 days, and say so if identity checks or an open payment dispute mean we need longer. If you are a client of a studio rather than an account holder, ask the studio first: they hold the record and can edit or delete it directly. If you cannot reach them, write to us and we will pass the request on and help where we can. Where local law gives you more — objecting to a particular use, restricting processing, withdrawing consent, or complaining to a data protection authority — those rights apply, and asking us costs you nothing. Our infrastructure runs in more than one country, so your data may be processed outside where you live. We use providers that commit to appropriate safeguards for those transfers.
Contact
Questions about this policy, or about a specific piece of data, go to studio@openink.ai. If you are writing about a client record, include the studio handle so we can find it. When this policy changes in a way that affects you, we update the effective date above and tell account holders before the change takes effect.